The Cuba ransomware operation, also tracked by some researchers as Tropical Scorpius or REF9019, has grown from a file-encrypting malware family into a mature double-extortion threat that steals data before encryption and pressures victims through leak sites. Researchers said the malware appends the .cuba extension, prepends encrypted files with the FIDEL.CA marker, and drops ransom notes including !! READ ME !!.txt and earlier variants such as !!! ALL YOUR FILES ARE ENCRYPTED !!!.TXT. Reporting tied the group to more than 100 victims and tens of millions of dollars in ransom payments, with U.S.-based organizations disproportionately affected and some incidents triggering downstream breach notifications across public-sector entities.
Technical analyses show Cuba ransomware can encrypt local disks, selected paths, network shares, and shares on specified IP addresses while using multithreading to speed encryption and avoid corruption. The malware uses ChaCha20 for file encryption and RSA/RSA-4096 to protect per-file keys, acquires elevated privileges, terminates database, virtualization, Outlook, and Exchange-related processes, and avoids execution on systems using Russian keyboard settings. Investigators also observed the operators using ROMCOM RAT, KerberCache, Mimikatz, ADFind, Net Scan, GetUserSPNs.ps1, ZeroLogon, and a CLFS privilege-escalation exploit for CVE-2022-24521, while broader reporting on Exchange exploitation highlighted how attackers commonly chain internet-facing flaws, deploy web shells, and exfiltrate data before launching follow-on ransomware activity.

TTPs, infrastructure, and targeting history in one profile.
18 events from the most recent confirmed update back to the earliest known activity.
SecurityScorecard published additional indicators of compromise for Cuba ransomware, linking BUGHATCH-serving host 64.235.39[.]82 and TLS certificate hash 5a4d4b947d94748eaeb9e12560098222f9982ab482af4aa5fe82ca2e430ba56a to four related IP addresses. The analysis said VirusTotal showed the host serving a Cuba-associated BUGHATCH sample in April 2023, strengthening the assessment that the certificate hash and associated IPs were Cuba-linked infrastructure.
On 1 December 2022, the FBI stated that Cuba ransomware had received $60 million from more than 100 victims.
On 2022-09-09, Elastic Security Labs published an analysis of BUGHATCH, a custom in-memory downloader/backdoor used in Cuba ransomware campaigns observed in February 2022. The report detailed its PowerShell-based delivery, HTTP(S) C2 with custom XOR encryption, execution and injection capabilities, and released a YARA rule for detection.
As of July 2022, Unit 42 reported that 60 organizations had been exposed on the Cuba ransomware leak site since 2019, including 40 in the United States. The report also noted 27 additional organizations beyond a prior count of 33.
Unit 42 observed the threat actor it tracks as Tropical Scorpius deploying Cuba ransomware beginning in early May 2022. The activity included use of ROMCOM RAT, KerberCache, a CLFS exploit for CVE-2022-24521, a security-killing driver, and ZeroLogon tooling.
A Cuba variant dated 7 February 2022 used the ransom note "!! READ ME !!.txt," the emails belingmor@cock.li and admin@cuba-supp.com, the Jabber address cuba_support@exploit.im, and a Tor URL.
On March 16, 2021, Microsoft published responder guidance for active exploitation of four on-premises Exchange Server vulnerabilities: CVE-2021-26855, CVE-2021-26858, CVE-2021-26857, and CVE-2021-27065. Microsoft also said March 2021 security updates were available and urged immediate patching.
In February 2021, a Cuba ransomware attack on Seattle-based Automatic Funds Transfer Services led multiple U.S. cities and agencies to issue breach notifications. Listed entities included the California Department of Motor Vehicles, the City of Seattle, and the Port of Everett.
By January 2021, Cuba operators had created a Tor site featuring photographs of Fidel Castro. A variant dated 20 January 2021 referenced the onion site and the email LR_FWS_H2M_ET@protonmail.ch.
A Cuba variant dated 13 November 2020 used the contact addresses helpadmin2@protonmail.com and helpadmin2@cock.li.
A Cuba variant dated 3 August 2020 used the contact email aam_sysadmin@protonmail.com.
A Cuba variant dated 10 July 2020 used the email achtung_admin@protonmail.com and the executable name kalt.exe. The same variant created the mutex Global\SvcctrlStartEvent_A3752DX.
A Cuba variant dated 4 June 2020 used the email mrddnet_support@protonmail.ch and the filename CC.exe.
A Cuba variant dated 10 February 2020 used the contact email iracomp2@protonmail.ch, showing continued evolution of the ransomware's operator infrastructure.
A Cuba variant dated 22 January 2020 used the .cuba extension, the ransom note "!!FAQ for Decryption!!.txt," and the contact email iracomp4@protonmail.ch.
Several 2020 Cuba ransom notes stated that the attackers had downloaded victims' databases, FTP servers, and file servers to their own servers. This marked the group's use of extortion based on alleged exfiltration.
The Cuba ransomware family emerged in late December 2019 to early 2020. Early variants encrypted files with the .cuba extension and used the FIDEL.CA marker.
Elastic Security analyzed a Cuba ransomware intrusion and detailed the payload's encryption modes, process-killing behavior, Russian keyboard check, and use of ChaCha20 plus RSA with a FIDEL.CA header. The report also published indicators and a YARA rule.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 69 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
id-ransomware.blogspot.com
Open sourcesecurityscorecard.com
Open sourceelastic.co
Open sourceelastic.co
Open sourceunit42.paloaltonetworks.com
Open sourcemsrc-blog.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.